oss-sec mailing list archives
Re: CVE id request: devotee (debian vote engine) cryptographically weak random numbers permit discovery of secret ballot submissions
From: Michael Gilbert <mgilbert () debian org>
Date: Mon, 21 May 2012 14:49:51 -0400
On Fri, May 18, 2012 at 6:39 PM, Kurt Seifried wrote:
This appears to be a service more than software, and although the source is available (see git link) it appears to be out of date? http://lists.debian.org/debian-www/2012/04/msg00200.html
Yes, the publicly available source repo is out of date right now, but that won't always be the case. Debian had a change in secretary, so workflows have changed, and ideally a more public mode of operation should be gotten back to.
Can you confirm the vulnerability is in the software you linked to, and that this has actually been downloaded/used outside of Debian?
Yes, it is indeed an issue in the software implementation itself. See original report for exact code lines that are flawed. I can neither confirm nor not confirm that devotee is used outside of debian, but it does seem like an obvious choice for online election management. It is however planned to be package for debian [0], and ubuntu automatically syncs debian, so eventually they will also get the package. it is important that an id be assigned so that they are aware that they will need to check the package when they do that sync. [0] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=470995
Current thread:
- CVE id request: devotee (debian vote engine) cryptographically weak random numbers permit discovery of secret ballot submissions Michael Gilbert (May 18)
- Re: CVE id request: devotee (debian vote engine) cryptographically weak random numbers permit discovery of secret ballot submissions Kurt Seifried (May 18)
- Re: CVE id request: devotee (debian vote engine) cryptographically weak random numbers permit discovery of secret ballot submissions Michael Gilbert (May 21)
- Re: CVE id request: devotee (debian vote engine) cryptographically weak random numbers permit discovery of secret ballot submissions Kurt Seifried (May 18)